CortexDocumentation

Deploy Cortex Sensor

Updated

For Cortex organization admins and IT teams. Employees should use Set up Cortex Sensor after Cortex appears on their device.

How deployment works

  1. Chaos Labs will create the Cortex organization and designate an initial admin.
  2. The designated admin will sign in to cortex.chaoslabs.xyz and complete organization onboarding.
  3. During onboarding, the admin will download a .pkg or .exe for the target devices.
  4. The admin will coordinate with IT to distribute Sensor using a compatible mobile device management system.
  5. Employees will open Cortex and complete device sign-in and capture setup.

Organization creation is not self-service. Most employees receive Cortex through managed deployment.

Who owns each step

OwnerResponsibility
Chaos LabsCreate the organization and designate the initial admin with your team
Organization adminComplete organization onboarding, download installers, and coordinate dashboard access
IT or device adminDeploy Cortex and manage device, keychain, network, process, and operating-system policies
EmployeeSign in, enable approved capture surfaces, and verify activity
DeveloperResolve conflicts between local services and Cortex ports

One person may fill both admin and IT roles. Cortex dashboard roles do not grant operating-system or MDM access.

Before deployment

Before rollout, confirm that the organization has completed any required employee notice or consent process for monitored AI activity. Contact the Chaos Labs team if the organization needs a description of what Cortex captures.

Get the installer

Sign in as the designated admin

  1. Go to cortex.chaoslabs.xyz.
  2. Sign in with the account designated during organization creation.
  3. Complete organization onboarding.
  4. Confirm the organization and identity settings before distributing Sensor.

If the designated admin cannot access the organization, contact the Chaos Labs team before distributing a package or creating another organization.

Obtain the deployment package

The onboarding flow provides the installer for each operating system:

PlatformRequirementPackageTested deployment method
macOSApple Silicon and macOS 12 or later.pkgJamf
WindowsWindows 10 or 11 on x64.exeMicrosoft Intune

Get installer dialog with platform packages and checksum

The installers are signed, and the macOS package is notarized. Jamf has been tested for macOS and Microsoft Intune has been tested for Windows. Test other deployment methods with a pilot group before rollout.

Distribute the installer provided during organization onboarding. Cortex does not have a public download page.

Verify each download against the SHA-256 checksum shown in the installer dialog before distributing it. On macOS run shasum -a 256 Cortex.pkg; on Windows run Get-FileHash Cortex.exe -Algorithm SHA256. The value must match exactly; if it does not, discard the download and download the installer again.

Distribute with MDM

Deployment steps depend on your MDM:

  1. Add the Cortex .pkg or .exe to the MDM.
  2. Assign it to a pilot group of representative devices.
  3. Apply the operating-system, keychain, routing, certificate, and network policies required for the capture paths in your rollout.
  4. Confirm Cortex installs and opens without requiring the employee to run a separate installer.
  5. Restart the device after installation when practical. A restart is not normally required, but it can activate newly installed capture services and application settings.
  6. Provide employees with the organization domain and Set up Cortex Sensor.

Sensor can be installed on the macOS and Windows versions listed above. Capture-path availability differs by platform. Use Supported providers and surfaces to choose what to test. Some browsers, desktop apps, command-line tools, and MCP hosts must restart after installation or configuration.

Validate a pilot device

On at least one representative managed device for each target platform:

  1. Confirm MDM installed Cortex.
  2. Open Cortex as an employee would.
  3. Complete organization sign-in.
  4. Configure each capture path included in the rollout.
  5. Send one new prompt through each source.
  6. Confirm each prompt appears in Home → Activity.
  7. Confirm Cloud sync is Up to date, Workspace is Enrolled, and Backlog is 0.
  8. Confirm the synced activity is available to an authorized Cortex dashboard user.
  9. Restart any applications named by Cortex, then confirm their capture paths become active.
  10. Quit and restart Cortex cleanly, then confirm capture recovers as expected.

Before expanding the rollout, verify enrollment, source configuration, local capture, and workspace sync. A successful installation or Running status alone does not verify capture.

Enrollment issues

If Cortex finds no identity providers, confirm that the employee entered the correct organization domain. The organization admin should verify the identity settings.

If sign-in does not complete, send the organization domain, identity provider, work account, and approximate attempt time to the Chaos Labs team.

Managed-device issues

Browser capture may require permission to change routing or certificate trust. Organization Admin access cannot override keychain, certificate-store, endpoint-security, or device-management policy.

If Cortex shows Port owners, include the port and process details when contacting the Chaos Labs team. Developers running local services can use Fix Sensor port conflicts.

Rollout and fleet operations

Fleet is limited to organization admins. Use it to:

  • Filter endpoints by All endpoints, Not reporting, Never reported, or Healthy.
  • Review Device, Person, Team, Last heartbeat, Last captured, Sensor version, State, Issue, and Action.
  • Select Get installer to reopen the organization installer flow.
  • Refresh the view after a deployment or repair.

Fleet page listing enrolled devices and their state

Enrollment and revocation happen outside Fleet. Contact the Chaos Labs team for revocation or other device-lifecycle actions that are not available in the dashboard.

Offboard or replace a device

For organization offboarding or service termination:

  1. Export your organization's Cortex data during the service term or within 30 days after termination.
  2. Resolve any unsynced local backlog before removing Cortex.
  3. On each device, open Proxy → Browser & Desktop, select Web apps → Configure, and turn off Web routing and Certificate for Chrome. Then select Stop Cortex and remove Cortex through the MDM or approved device-management path. Stopping or quitting Cortex alone does not remove browser routing or certificate trust.

After the 30-day export window, Cortex data may be irretrievably erased.

See Control capture and sync for Sensor controls.

Contact the Chaos Labs team before removing a device that has an unsynced backlog or cannot be disconnected normally.

Was this helpful?